Out-of-Bounds Read Vulnerability in BACnet Stack by BACnet
CVE-2026-41475
8.7HIGH
What is CVE-2026-41475?
The BACnet Stack, an open source protocol stack library, contains an out-of-bounds read flaw in its WritePropertyMultiple service decoder. This vulnerability allows unauthenticated remote attackers to send a specially crafted BACnet/IP packet containing a truncated property payload. The vulnerable function, wpm_decode_object_property(), does not validate buffer boundaries, which can result in reading past allocated memory. Such exploitation may lead to crashes or may expose sensitive information on embedded BACnet devices. This critical issue has been addressed in version 1.4.3 of the BACnet Stack.
Affected Version(s)
bacnet-stack >= 1.4.0, < 1.4.3
